| 1 | # /etc/systemd/system/snowbound-relay.service: the Live Share relay behind a TLS proxy on |
| 2 | # this machine (README.md). Options go on ExecStart, or as SNOWBOUND_RELAY_* in Environment. |
| 3 | [Unit] |
| 4 | Description=Snowbound Live Share relay |
| 5 | After=network-online.target |
| 6 | Wants=network-online.target |
| 7 | |
| 8 | [Service] |
| 9 | ExecStart=/usr/local/bin/snowbound-relay --listen 127.0.0.1:23592 --trust-forwarded true |
| 10 | Restart=always |
| 11 | RestartSec=2 |
| 12 | DynamicUser=yes |
| 13 | # Two threads a connection, and a few more. |
| 14 | TasksMax=600 |
| 15 | LimitNOFILE=1024 |
| 16 | MemoryMax=512M |
| 17 | NoNewPrivileges=yes |
| 18 | ProtectSystem=strict |
| 19 | ProtectHome=yes |
| 20 | PrivateTmp=yes |
| 21 | PrivateDevices=yes |
| 22 | ProtectKernelTunables=yes |
| 23 | ProtectKernelModules=yes |
| 24 | ProtectControlGroups=yes |
| 25 | RestrictAddressFamilies=AF_INET AF_INET6 |
| 26 | RestrictNamespaces=yes |
| 27 | LockPersonality=yes |
| 28 | MemoryDenyWriteExecute=yes |
| 29 | SystemCallArchitectures=native |
| 30 | CapabilityBoundingSet= |
| 31 | |
| 32 | [Install] |
| 33 | WantedBy=multi-user.target |